CVE-2022-0223

A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could allow an attacker to create or overwrite critical files that are used to execute code, such as programs or libraries and cause unauthenticated code execution. Affected Products: EcoStruxure Power Commission (Versions prior to V2.22)
Configurations

Configuration 1 (hide)

cpe:2.3:a:schneider-electric:ecostruxure_power_commission:*:*:*:*:*:*:*:*

History

07 Feb 2023, 02:36

Type Values Removed Values Added
CPE cpe:2.3:a:schneider-electric:ecostruxure_power_commission:*:*:*:*:*:*:*:*
First Time Schneider-electric
Schneider-electric ecostruxure Power Commission
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
References (MISC) https://download.schneider-electric.com/files?p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2022-165-05_EcoStruxure_Power_Commission_Security_Notification.pdf - (MISC) https://download.schneider-electric.com/files?p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2022-165-05_EcoStruxure_Power_Commission_Security_Notification.pdf - Patch, Vendor Advisory

30 Jan 2023, 23:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-01-30 23:15

Updated : 2023-12-10 14:48


NVD link : CVE-2022-0223

Mitre link : CVE-2022-0223

CVE.ORG link : CVE-2022-0223


JSON object : View

Products Affected

schneider-electric

  • ecostruxure_power_commission
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')